# Security Policy ## Threat model context This plugin runs **rootful Podman**. Its API socket (`/var/run/podman/podman.sock`) is root-equivalent on the host, in the same way Docker's `docker.sock` is. See [docs/ARCHITECTURE.md](../docs/ARCHITECTURE.md#19-sicherheitsbetrachtungen-phase-1-rootful) for the full rationale. Treat any bug that affects socket permissions, WebUI authentication, or container-to-host isolation as security-sensitive by default. ## Reporting a vulnerability Please **do not** open a public GitHub issue for security vulnerabilities. Instead, use one of: - GitHub [private security advisories](https://github.com/OWNER/unraid-podman/security/advisories/new) for this repository, or - Email the maintainers at `security@OWNER-DOMAIN` (placeholder — update once a contact address exists). Please include: - A description of the issue and its potential impact. - Steps to reproduce (Unraid version, plugin version, storage backend). - Whether the issue requires local access, network access, or a malicious container image to trigger. ## Supported versions This project has not yet cut a stable release. Until a `1.0.0` release, only the latest `main` branch / most recent tag is supported with security fixes. ## Disclosure process We aim to acknowledge reports within 5 business days and to agree on a coordinated disclosure timeline before any public write-up.